note 33277 added to function.strip-tags

From: Date: Fri, 20 Jun 2003 16:37:38 +0000
Subject: note 33277 added to function.strip-tags
Groups: php.notes 
Request: Send a blank email to php-notes+get-50762@lists.php.net to get a copy of this message
To fix the <scr<script></script>ipt> bug, I'm going to use the following function for my upcoming forum project: function realsafehtml($str) { // Don't do anything if there's no difference or if the original string is empty $oldstr = ""; while($str != $oldstr) // Loop until it got no more effect { $oldstr = $str; //nuke script and header tags and anything inbetween $str = preg_replace("'<script[^>]*?>.*?</script>'si", "", $str); $str = preg_replace("'<head[^>]*?>.*?</head>'si", "", $str); //listed of tags that will not be striped but whose attributes will be $allowed = "br|b|i|p|u|a|center|hr"; //start nuking those suckers. don you just love MS Word's HTML? $str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "", $str); $str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str); } return $str; } It's obviously more expensive than the original function, but also a lot more secure :) I hope this can help someone - didn't test it much yet, though. ---- Manual Page -- http://www.php.net/manual/en/function.strip-tags.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+33277 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+33277&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+33277&report=yes

« previous php.notes (#50762) next »